CVE-2016-6312: Medium severity red hat enterprise linux vulnerability
A regression was found on RHEL-5.11 making apr-util and httpd vulnerable to billion laughs attack, also known as CVE-2009-1955, again.
Other sources
The moddontdothat component of the moddavsvn Apache module in Subversion as packaged in Red Hat Enterprise Linux 5.11 does not properly detect recursion during entity expansion, which allows remote authenticated users with access to the webdav repository to cause a denial of service (memory consumption and httpd crash). NOTE: Exists as a regression to CVE-2009-1955.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6312?
CVE-2016-6312 is considered a medium severity vulnerability as it introduces a potential denial-of-service condition.
How do I fix CVE-2016-6312?
To fix CVE-2016-6312, you should upgrade to a patched version of RHEL or the affected Apache modules that address this vulnerability.
Which systems are affected by CVE-2016-6312?
CVE-2016-6312 specifically affects Red Hat Enterprise Linux version 5.11 that uses the apr-util and httpd components.
What type of attack does CVE-2016-6312 relate to?
CVE-2016-6312 is associated with the billion laughs attack, a form of denial-of-service attack that exploits XML processing.
Is CVE-2016-6312 a new vulnerability?
CVE-2016-6312 is a regression vulnerability that reopens previously addressed issues from CVE-2009-1955.